Iranian Hackers Tried to Give Hacked Trump Campaign Emails to Dems

Plus: The FBI dismantles the largest-ever China-backed botnet, the DOJ charges two men with a $243 million crypto theft, Apple’s MacOS Sequoia breaks cybersecurity tools, and more.

Security Latest – ​Read More

Patch this Critical Safeguard for Privileged Passwords Authentication Bypass Flaw

Researchers have released technical details about CVE-2024-45488, a critical authentication bypass vulnerability affecting One Identity’s Safeguard for Privileged Passwords (SPP), which could allow attackers to gain full administrative access.

Cyware News – Latest Cyber News – ​Read More

Germany Seizes 47 Crypto Exchanges Used by Ransomware Gangs

These exchanges allowed users to trade cryptocurrencies anonymously, creating a safe environment for cybercriminals to launder their proceeds without fear of prosecution.

Cyware News – Latest Cyber News – ​Read More

CISA Adds Windows, Apache HugeGraph-Server, Oracle JDeveloper, Oracle WebLogic Server, and MSSQL Server Bugs to its KEV Catalog

These vulnerabilities can lead to remote code execution and privilege escalation, posing a significant risk to affected systems. For example, the Oracle JDeveloper vulnerability can allow attackers to compromise the software and take over the system.

Cyware News – Latest Cyber News – ​Read More

Clever ‘GitHub Scanner’ Campaign Abusing Repositories to Push Malware

A sophisticated campaign is using GitHub repositories to spread the Lumma Stealer malware, targeting users interested in open-source projects or receiving email notifications from them.

Cyware News – Latest Cyber News – ​Read More

Microsoft Entra ID’s Administrative Units Weaponized to Gain Stealthy Persistence

Datadog Security Labs recently revealed a security risk within Microsoft Entra ID, showing how its administrative units (AUs) can be weaponized by attackers to create persistent backdoor access.

Cyware News – Latest Cyber News – ​Read More

Adversarial attacks on AI models are rising: what should you do now?

With AI’s growing influence across industries, malicious attackers continue to sharpen their tradecraft to exploit ML models.Read More

Security News | VentureBeat – ​Read More

Ivanti’s Cloud Service Appliance Attacked via Second Vuln

The critical bug, CVE-2024-8963, can be used in conjunction with the prior known flaw to achieve remote code execution (RCE).

darkreading – ​Read More

Citrine Sleet Poisons PyPI Packages With Mac & Linux Malware

A North Korean advanced persistent threat (APT) actor (aka Gleaming Pisces) tried to sneak simple backdoors into public software packages.

darkreading – ​Read More

More than $44 million in cryptocurrency stolen from Singaporean platform BingX

Singaporean crypto platform BingX said Friday that more than $44 million was stolen from their platform in a cyberattack.

The Record from Recorded Future News – ​Read More